Usage Scenario
SPI uniquely identifies an SA. When an SPI is configured for an SA, the SPI is carried in each sent protocol packet. The receiver checks the protocol packet authenticity based on the SPI. When the ipsec sa sa-name command is used to create an SA, run the sa spi command to configure the SPI.
Precautions
Set parameters for both inbound and outbound SAs.
The SPI for incoming protocol packets on the local end must be identical with that for outgoing protocol packets on the peer end and vice versa.